CVE-2024-12728: Sophos Firewall Firmware
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).
Affected products
- Sophos Firewall Firmware: before 20.0.3 (fixed in 20.0.3)
Published 2024-12-19. Last modified 2026-06-17.